Which statement best describes encryption requirements for CUI in transit and at rest?

Study for the DOD Instruction 5200.48 Controlled Unclassified Information (CUI) exam. Prepare with flashcards and multiple choice questions, each with detailed hints and explanations. Ensure success on your test day!

Multiple Choice

Which statement best describes encryption requirements for CUI in transit and at rest?

Explanation:
Encryption protects CUI wherever it lives or travels. Data in transit must be encrypted to prevent eavesdropping and tampering as it moves across networks, using approved protocols and configurations (for example, standards-compliant TLS or IPsec). Data at rest needs encryption on storage media, backups, and cloud storage so that unauthorized users cannot read it even if they gain physical access. Using approved encryption means relying on cryptographic algorithms and modules that meet DoD/NIST standards and are validated for security. This approach aligns with policy, reduces risk, and demonstrates proper safeguarding of CUI. Encryption applied only to one state leaves gaps in protection, whereas encrypting both in transit and at rest provides comprehensive protection.

Encryption protects CUI wherever it lives or travels. Data in transit must be encrypted to prevent eavesdropping and tampering as it moves across networks, using approved protocols and configurations (for example, standards-compliant TLS or IPsec). Data at rest needs encryption on storage media, backups, and cloud storage so that unauthorized users cannot read it even if they gain physical access. Using approved encryption means relying on cryptographic algorithms and modules that meet DoD/NIST standards and are validated for security. This approach aligns with policy, reduces risk, and demonstrates proper safeguarding of CUI. Encryption applied only to one state leaves gaps in protection, whereas encrypting both in transit and at rest provides comprehensive protection.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy